Hi...I selected a James Comey headline from the msn.com startup page on Apr 16, 2018. Then I received a msg saying that Windows Defender detected Trojan:JS/Flafisi.D. I immediately closed Microsoft Edge and opened Defender to see about removing Trojan:JS/Flafisi.D. However, I don't see any instructions on removing it. So I started a full scan of my computer. Unfortunately some 5hrs later, it was still running and only appears to half way thru. However, I have mistakenly closed the scan. I will run it again later. How do I ensure that Trojan:JS/Flafisi.D is removed?
I’m seeing Trojan:JS/Flafisi.D detections and Tech Support Scams on the Edge browser Start page
Update: A member of Microsoft's MSN Engineering Team (RodrigoLode(MSFT) has responded to acknowledge the malvertising issues associated with MSN portal. They have also requested ***" If anyone is still experiencing this, please reply here."***For more specifics on information requested please refer to the reply from Rodrigo at the following link:
In addition to reporting the fake pop-ups themselves I would advise that you take note if there is a significant loss of performance on computer after encountering, in particular, the fake Adobe Flash Player update. If things seem sluggish you may have been subject to one of the more prevalent malicious activities known as crypto-mining/coin mining.
Invisible resource thieves: The increasing threat of cryptocurrency miners
Especially important to report these occurrences or any other odd behaviors after using MSN website.
Moderator Edit: Provided update.
Just reading the “Comey trolls Trump” article on the Edge Start page and this pops up:
This one was easy to handle because it was just the old-fashioned dialog loop based scam:
– but what’s coming next Microsoft?
GreginMich
[Original Title: Surprised again]
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
386 answers
Sort by: Oldest
-
Anonymous
2018-04-16T12:16:20+00:00 -
Anonymous
2018-04-17T04:34:59+00:00 Had this red warning page pop up three times in the last week and a half. The last time was today April 16 about 2:30PM. Was on the MSN page (as I was the other two times) clicking on a news article in the upper right side of the page. The window with side arrows to advance to the next article or backup to the previous article. The article today was about Trump's lawyer Cohen. I don't remember what the other articles earlier were and did not know then of this thread. Also Defender found and quarantined that Trojan:JS/Flafisi.D virus and I removed it. Today was the first time for the Trojan though.
-
Anonymous
2018-04-17T10:46:41+00:00 Hi all,
I'm on the MSN Engineering team and would love help if anyone encounter this again. We've been tracking this since it started in mid February. We do quite a bit of work to scan the ads we get from our exchanges, but some behave differently for certain users than they do when we do our scanning. In the future, please continue to submit feedback so we can narrow the scans on our end and potentially reproduce and remove this once and for all. If your page was hijacked and you couldn't view the article, please mention the article headline you've visited as well.
If anyone is still experiencing this, please reply here.
Thanks,
-Rodrigo (MSN Engineering)
Hi Rodrigo, I have an odd question involving this. While on an article it opened up to the virus while I wasn't looking, and when I found it it asked me what I wanted to do with it when the virus finished downloading and so I hit cancel, and it still was quarantined. I hit "restore" in stead of destroy on accident but it doesn't show up in allowed threats. It still said to restart now to delete it though so I did. Is it gone? If not how should I go about it?
Thanks.
-
Anonymous
2018-04-17T13:33:43+00:00 Hi I am seeing Trojan horse and viral tool on my pc. Please help me get them out completely. Thank you.
-
Anonymous
2018-04-17T13:42:36+00:00 When we restore a quarantined item, this creates a temporary path exclusion for the “threat”, which will remain in effect for several days – and since this exclusion won’t appear in the user interface, there’s no easy way to undo a mistake here. In days gone by, we could remove the temporary exclusion by removing its entry in the registry, but we no longer have access to Defender’s registry folder. We do have a local thread that suggests gaining access to the TemporaryPaths subkey by loading a registry hive from the Advanced Startup Options interface; but I’m certainly not going to recommend a solution that might involve more risk than just leaving the temporary path exclusion in place until it expires.
In order to determine whether or not a temporary path exclusion was actually created; navigate to this registry location:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\TemporaryPaths
If so, then I think the best course of action here would be to just scan for any potential threats with multiple malware-removal tools; beginning with Malwarebytes Free, and including the Kaspersky Virus Removal Tool:
If you have any further questions regarding this issue, then please start your own thread by clicking on the “Ask a Question” link at the upper right of the page.
GreginMich